Yacine Elhamer
|
6712801b01
|
tests/fixtures.py: update path forming for the cape sample
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-06-20 20:30:06 +01:00 |
|
Yacine Elhamer
|
f29db693c8
|
fix git submodules error
|
2023-06-20 20:25:19 +01:00 |
|
Yacine Elhamer
|
0502bfd95d
|
remove cape report from get_md5_hash() function
|
2023-06-20 20:24:38 +01:00 |
|
Yacine Elhamer
|
78a3901c61
|
cape/helpers.py: add a find_process() function for quick-fetching processes from the cape report
|
2023-06-20 15:59:22 +01:00 |
|
Yacine Elhamer
|
0a4e3008af
|
fixtures.py: update CAPE's feature count and presence tests
|
2023-06-20 13:51:16 +01:00 |
|
Willi Ballenthin
|
2ce4f8769d
|
Merge pull request #1513 from mandiant/ida-test-runner
tests: refine the IDA test runner
|
2023-06-20 14:28:12 +02:00 |
|
Willi Ballenthin
|
4dedc24f9f
|
Merge branch 'master' into ida-test-runner
|
2023-06-20 14:28:05 +02:00 |
|
Yacine Elhamer
|
d03ba5394f
|
cape/global_.py: add warning messages if architecture/os/format are unknown
|
2023-06-20 13:26:25 +01:00 |
|
Yacine Elhamer
|
2262e6c7d0
|
Merge branch 'test-cape-extractor' into cape-extractor
|
2023-06-20 13:22:15 +01:00 |
|
Yacine Elhamer
|
31a349b13b
|
cape feature tests: fix feature count function typo
|
2023-06-20 13:21:52 +01:00 |
|
Yacine Elhamer
|
1ba143ef26
|
Merge branch 'test-cape-extractor' into cape-extractor
|
2023-06-20 13:20:49 +01:00 |
|
Yacine Elhamer
|
1532ce1bab
|
add tests for extracting argument values
|
2023-06-20 13:20:33 +01:00 |
|
Yacine Elhamer
|
fa9b920b71
|
cape/thread.py: do not extract return values, and extract argument values as Strings
|
2023-06-20 13:17:53 +01:00 |
|
Yacine Elhamer
|
40b2d5f724
|
add a remote origin to submodule, and switch to that branch
|
2023-06-20 12:40:47 +01:00 |
|
Yacine Elhamer
|
0623a5a8de
|
point capa-testfiles submodule towards dynamic-feautre-extractor branch
|
2023-06-20 12:13:57 +01:00 |
|
Yacine Elhamer
|
cfa1d08e7e
|
update testfiles submodule to point at dev branch
|
2023-06-20 11:28:40 +01:00 |
|
Yacine Elhamer
|
6196814672
|
cape/file.py: fix KeyError bug
|
2023-06-20 10:51:18 +01:00 |
|
Yacine Elhamer
|
f5af2bf393
|
Merge branch 'test-cape-extractor' into cape-extractor
|
2023-06-20 10:47:56 +01:00 |
|
Yacine Elhamer
|
374fb033c1
|
add support for gzip compressed cape samples, and fix QakBot sample path
|
2023-06-20 10:29:52 +01:00 |
|
Yacine Elhamer
|
4db80e75a4
|
add mode and encoding parameters to open()
|
2023-06-20 10:13:06 +01:00 |
|
Yacine Elhamer
|
8547277958
|
tests/fixtures.py bugfix: remove redundant lambda function
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
|
2023-06-20 10:10:42 +01:00 |
|
Yacine Elhamer
|
ec3366b0e5
|
Update tests/fixtures.py
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
|
2023-06-20 10:09:27 +01:00 |
|
Yacine Elhamer
|
48bd04b387
|
tests/fixtures.py: return direct extractor with no intermediate variable
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
|
2023-06-20 10:09:00 +01:00 |
|
Yacine Elhamer
|
41a481252c
|
Update CHANGELOG.md
Co-authored-by: Moritz <mr-tz@users.noreply.github.com>
|
2023-06-20 10:08:12 +01:00 |
|
Yacine Elhamer
|
a7cf3b5b10
|
features/insn.py: revert added strace-based API feature
|
2023-06-20 10:04:37 +01:00 |
|
Yacine Elhamer
|
ba63188f27
|
cape/file.py: fix bug in call to helpers.generate_symbols()
Co-authored-by: Willi Ballenthin <willi.ballenthin@gmail.com>
|
2023-06-20 10:02:57 +01:00 |
|
Yacine Elhamer
|
9cc34cb70f
|
cape/file.py: fix imports ordering and format
|
2023-06-20 00:19:55 +01:00 |
|
Yacine Elhamer
|
b9a4d72b42
|
cape/file.py: add usage of helpers.generate_symbols()
|
2023-06-20 00:12:21 +01:00 |
|
Yacine Elhamer
|
8eef210547
|
update changelog
|
2023-06-19 23:57:51 +01:00 |
|
Yacine Elhamer
|
ef999ed954
|
rules/__init__.py: remove redundant HBI features
|
2023-06-19 23:56:10 +01:00 |
|
Yacine Elhamer
|
33de609560
|
Revert "removed redundant HBI features"
This reverts commit c88f859dae.
|
2023-06-19 23:55:22 +01:00 |
|
Yacine Elhamer
|
624151c3f7
|
Revert "update changelog"
This reverts commit 49b77d5477.
|
2023-06-19 23:55:12 +01:00 |
|
Yacine Elhamer
|
c88f859dae
|
removed redundant HBI features
|
2023-06-19 23:55:06 +01:00 |
|
Yacine Elhamer
|
49b77d5477
|
update changelog
|
2023-06-19 23:49:19 +01:00 |
|
Yacine Elhamer
|
d4c4a17eb7
|
bugfixes and add cape sample tests
|
2023-06-19 23:42:27 +01:00 |
|
Yacine Elhamer
|
3c8abab574
|
fix bugs and refactor code
|
2023-06-19 23:40:09 +01:00 |
|
Yacine Elhamer
|
38596f8d0e
|
add features for the QakBot sample
|
2023-06-19 19:32:56 +01:00 |
|
Yacine Elhamer
|
4acdca090d
|
bug fixes
|
2023-06-19 17:14:59 +01:00 |
|
Yacine Elhamer
|
f02178852b
|
update changelog
|
2023-06-19 17:01:05 +01:00 |
|
Yacine Elhamer
|
98e7acddf4
|
fix codestyle issues
|
2023-06-19 16:59:27 +01:00 |
|
Yacine Elhamer
|
9458e851c0
|
update test sample's path
|
2023-06-19 16:46:24 +01:00 |
|
Yacine Elhamer
|
a04512d7b8
|
add unit tests for the cape feature extractor
|
2023-06-19 16:43:54 +01:00 |
|
Moritz
|
1bc0174f6f
|
Merge pull request #1562 from mandiant/dependabot/pip/ruamel-yaml-0.17.32
build(deps): bump ruamel-yaml from 0.17.28 to 0.17.32
|
2023-06-19 17:24:22 +02:00 |
|
Moritz
|
90842f313a
|
Merge pull request #1543 from mandiant/dependabot/pip/pydantic-1.10.9
build(deps): bump pydantic from 1.10.7 to 1.10.9
|
2023-06-19 17:23:51 +02:00 |
|
Moritz
|
6aa2f6457c
|
Merge pull request #1521 from mandiant/dependabot/pip/pytest-cov-4.1.0
build(deps-dev): bump pytest-cov from 4.0.0 to 4.1.0
|
2023-06-19 17:23:19 +02:00 |
|
Moritz
|
b7c600e60b
|
Merge pull request #1520 from mandiant/dependabot/pip/requests-2.31.0
build(deps-dev): bump requests from 2.28.0 to 2.31.0
|
2023-06-19 17:22:55 +02:00 |
|
Moritz
|
d397b46b63
|
Merge pull request #1518 from mandiant/dependabot/pip/types-requests-2.31.0.1
build(deps-dev): bump types-requests from 2.28.1 to 2.31.0.1
|
2023-06-19 17:22:32 +02:00 |
|
dependabot[bot]
|
7a6b7c5ef0
|
build(deps): bump ruamel-yaml from 0.17.28 to 0.17.32
Bumps [ruamel-yaml](https://sourceforge.net/p/ruamel-yaml/code/ci/default/tree) from 0.17.28 to 0.17.32.
---
updated-dependencies:
- dependency-name: ruamel-yaml
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-06-19 14:58:25 +00:00 |
|
Yacine Elhamer
|
d6fa832d83
|
cape: move get_processes() method to file scope
|
2023-06-19 13:50:46 +01:00 |
|
Yacine Elhamer
|
dbad921fa5
|
code style changes
|
2023-06-15 13:21:17 +01:00 |
|